﻿using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc;

namespace Magic.Oidc.ResourceServer.Controllers
{
    [ApiController]
    [Route("resources")]
    public class ResourceController : Controller
    {
        [Authorize]
        [HttpGet]
        public IActionResult GetSecretResources()
        {
            var user = HttpContext.User?.Identity?.Name;
            return Ok($"user: {user}");
        }
    }
}
